CVE-2016-6394: Critical severity cisco firesight system vulnerability
Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6394?
CVE-2016-6394 is considered a medium severity vulnerability due to its potential for session hijacking.
How do I fix CVE-2016-6394?
To mitigate CVE-2016-6394, upgrade the Cisco Firepower Management Center or FireSIGHT System Software to the latest version following Cisco's security advisory.
What type of attack does CVE-2016-6394 facilitate?
CVE-2016-6394 can lead to session fixation attacks, allowing remote attackers to hijack user sessions.
Which versions of Cisco FireSIGHT System Software are affected by CVE-2016-6394?
Affected versions of Cisco FireSIGHT System Software range from 5.2.0 to 6.1.0, including various updates within those major versions.
Can CVE-2016-6394 affect user credentials?
Yes, CVE-2016-6394 can potentially allow attackers to compromise user credentials by taking control of an active web session.